Integrate with Microsoft Intune

In this topic, you will learn how to set up the integration between Portnox™ Cloud and Microsoft Intune.

Integrate with Intune

In this section, you will set up the integration between Portnox™ Cloud and Microsoft Intune.

  1. In the Cloud portal top menu, click on the Settings option.

  2. In the Cloud portal left-hand side menu, click on the Integration Services > MS INTUNE INTEGRATION SERVICE option.

  3. Enable Microsoft Intune integration
    1. Under the MS Intune integration service heading and description, click on the Edit link.

    2. Click on the Disabled/Enabled switch to put it in the Enabled position.

    3. Click on the Save button.
  4. In the Application provisioning step, select your Azure environment type from the drop-down menu.

    Note:
    We recommend that you select the same environment type as you selected when integrating with Entra ID.
    • Public: This is the standard Microsoft Azure environment used by most organizations worldwide. Select this option unless your organization specifically uses one of the other environments listed below.

    • US Government: This is a physically isolated instance of Microsoft Azure operated exclusively for US federal, state, local, and tribal government agencies, and their partners. It meets strict compliance requirements such as FedRAMP High, CJIS, and DoD SRG.

      Note:
      Because this environment does not permit Portnox Cloud to register applications automatically, only the Manually create Portnox Cloud application(s) in your Entra ID tenant option is available when this environment type is selected.
    • Custom: This option is for organizations operating in sovereign or national cloud environments with custom Entra ID endpoints – for example, organizations in China using Microsoft Azure operated by 21Vianet, which operates under Chinese data residency and sovereignty laws. These environments use entirely separate portals, app registrations, and endpoint domains from the standard commercial cloud; a global Entra ID app registration cannot be reused here. When you select this option, you must manually enter endpoint values. For information on these endpoint values and how to obtain them, see the following topic: Custom Azure endpoints for Entra ID and Intune integrations.

      Note:
      Because this environment does not permit Portnox Cloud to register applications automatically, only the Manually create Portnox Cloud application(s) in your Entra ID tenant option is available when this environment type is selected.
  5. Select the application provisioning method and click on the Start integration button.

  6. Grant the Portnox Cloud integration application consent to read Intune data and perform SCEP validation.
    1. Click on the Grant consent button.

      Your browser will display a Microsoft prompt to select an account.

    2. Click on the admin account for your Azure tenant.

      Your browser will display a Microsoft prompt asking you to confirm the required permissions.

    3. Click on the Accept button to confirm permissions that the Portnox Cloud integration application will have to your Intune data.

Result: Your Intune integration is now active.

You can see Intune-related information for specific devices on the Devices screen by selecting an Intune-managed device from the list and scrolling the right-hand side pane.

Automatically create Intune configuration policies

In this section, you will automatically create Intune configuration policies, which will let you skip manual onboarding.

Important:
The Intune configuration API provided by Microsoft is still in Beta stage, and so you still need to perform some manual steps after automatically creating policies. See the next section on information how to perform these steps.
Important:
To create SCEP policies in Intune, you need to turn on the Portnox Cloud SCEP services. For information on how to do this, see the following section: Turn on the Portnox Cloud SCEP services.
  1. Click on the Create configuration(s) button in the Intune configuration section, which is located at the end of the MS Intune integration service section.

  2. In the Add Intune configuration window, select the Platform(s) and Configuration type(s) to create:

    1. If you selected Wireless network access, enter the Wireless name (SSID) to include in the configurations.
    2. If you selected the Windows platform and Wired network access or Wireless network access configuration types, select the Authentication mode (User, Computer, or User and Computer).
    3. If instead of the default option: Use the same configuration for all selected platforms, you chose the option: Each Platform will have its own unique configuration, you can then choose different configuration types for each platform (including different SSIDs and authentication modes).

  3. Click on the Create configuration(s) button.

    You will be asked to authenticate with Intune, and then Portnox Cloud will automatically create the configurations.

    The configurations will have the following names:

    Configuration type Configuration name
    RADIUS root certificate platform_name Radius Trusted Root
    Organization (Tenant) root certificate platform_name tenant_name Trusted Root
    Wireless network access platform_name WiFi
    Wired network access platform_name Wired
    SCEP - User platform_name Scep User
    SCEP - Device platform_name Scep Machine

    You can see the configurations in Intune by going to: Devices > Manage devices > Configuration.